Reference: 2026 Benchmarks · Updated July 2026

2026 Incident Cost Benchmarks: Cross-Source Aggregate

$4.99M
IBM CODB 2026 global
$11.5M
IBM CODB 2026 US
$2.73M
Sophos ransomware recovery
$16B
IC3 2024 total reported

No single published source captures the complete picture of incident cost in 2026. The honest answer to "what does an incident cost?" depends on what kind of incident, in what sector, in what region, with what regulatory implications, and on whose definition of "cost." This page consolidates the major published 2024-2026 benchmarks across IBM, Verizon, Sophos, Coveware, FBI IC3, Resilience, and Mandiant, with explicit notes on what each measures and where they diverge. Use each source for its question; triangulate where you can; document your assumptions when you cannot.

The Master Benchmark Table

The single-table cross-source view. Each row is a published benchmark. The "Measure" column documents what is being counted; the "Source" column documents who published and when.

BenchmarkNumberMeasureSource
Global average breach cost$4.99MAll-cause breach across surveyed orgs (record high, +12% YoY)IBM CODB 2026
US average breach cost$11.5MUS-headquartered surveyed orgs (highest of any country)IBM CODB 2026
Healthcare breach cost (highest sector)$6.64MHealthcare cohort average (down 10.5% YoY, still #1)IBM CODB 2026
Public sector breach cost (lowest sector)$2.86MPublic sector cohort average (2025 edition, pending 2026 sector split)IBM CODB 2025
Ransomware mean recovery cost (cross-sector)$1.53MRecovery cost excluding ransom (down from $2.73M in 2024)Sophos State of Ransomware 2025
Ransomware mean recovery cost (healthcare)$1.02MHealthcare-specific recovery (down 60% from $2.57M in 2024)Sophos State of Ransomware in Healthcare 2025
Cross-sector median ransom payment$150KCoveware Q2 2026 (avg payment $1,880,612)Coveware Q2 2026
Healthcare mean ransom payment$150KSophos healthcare cohort (down from $1.47M in 2024)Sophos Healthcare 2025
Ransomware payment rateRecord lowQ2 2026 new record low; data-exfiltration-only rate 15%; down from ~76% in 2019Coveware Q2 2026
Median ransomware downtime16-24 daysFrom encryption event to operational restorationCoveware quarterly
Insider threat (credential theft)$779KCost per incidentPonemon Cost of Insider Risks 2025
P1 / Sev 1 incident cost$794KAverage cost per P1 eventPagerDuty State of Digital Operations 2024
Average BEC loss~$137KAverage loss per BEC complaint reportedFBI IC3 Internet Crime Report 2024
Total IC3-reported cyber losses (US)$16B+Calendar year 2024 reportedFBI IC3 2024
Mean breach detection lifecycle247 daysDetection plus containment, cross-industry (up about 2.5% YoY)IBM CODB 2026
Cost reduction with AI/automation-$1.93M avgVersus orgs without extensive AI/automationIBM CODB 2026

What Each Source Actually Measures

Apparent contradictions across published sources usually reflect different methodologies. The honest reading requires understanding what each source counts and what it excludes.

SourceMethodologyBest For
IBM Cost of a Data BreachAnnual survey of approximately 600 organisations that experienced a breach; activity-based costing across four phases (detection/escalation, notification, post-breach response, lost business)Per-breach average cost, sector and country breakouts, control-impact analysis
Verizon DBIRAggregates approximately 30,000 incidents annually from 100+ contributing organisations including law enforcement, insurance carriers, and IR firmsBreach-cause distribution, threat-actor analysis, attack-pattern frequency
Sophos State of RansomwareAnnual survey of approximately 5,000 IT and cybersecurity leaders globallyRansomware attack rate, recovery cost, payment rate by sector and region
Coveware quarterlyReal cases Coveware handled as IR firm; not a survey, actual data from negotiationsMedian ransom paid, downtime, payment rate, threat-actor distribution
Resilience Cyber Risk ReportUnderwriter view; claims data and policy-portfolio analysisInsurance-claim severity by control posture; underwriting-relevant view
FBI IC3 Internet Crime ReportVoluntary complaints filed at ic3.gov; necessarily underrepresents actual lossesReported cyber-crime totals, BEC losses, scam categorisation
Mandiant M-TrendsMandiant's IR engagement data; nation-state and APT focusDwell time, attack-vector distribution, threat-actor TTPs
Ponemon Cost of Insider RisksAnnual survey of approximately 1,000 organisations on insider-risk experienceInsider incident cost by category (negligent, malicious, credential theft)
PagerDuty State of Digital OperationsSurvey of operations leaders; incident-management focusPer-P1-incident cost; on-call practice trends

The 2025-2026 Year-Over-Year Story

The prior-year story was a 9% decline in IBM's CODB headline, the first drop in the report's history. IBM CODB 2026 (released 29 July 2026) reversed it: the global average rose 12% to a record $4.99M, and the mean detection-and-containment lifecycle lengthened about 2.5% to 247 days. IBM attributes the turnaround largely to AI-enabled attacks, one in four malicious breaches were AI-enabled and cost about $6M each on average, roughly $1M above the overall average. AI and automation still cut cost for defenders that deploy it extensively (about $1.93M saved per breach), but that saving no longer offsets the rising attack side. The US average climbed to $11.5M, more than double the global figure.

Several other 2024-2026 trends are visible across multiple sources. Ransomware payment rates remain historically low (Coveware reports the payment rate fell to a new record low in Q2 2026, with the data-exfiltration-only rate down to 15%, and down from 76% in 2019), driven by improved backups, OFAC compliance, and customer/regulator preference. Median ransom amounts fell further in Q2 2026 (Coveware median $150,000, down about 50% on the quarter) even as average payments jumped to $1,880,612 on a handful of very large law-firm settlements: Sophos reports average recovery cost dropped to $1.53M in 2025 from $2.73M in 2024, a 44% decline, as fewer victims pay and more restore from backups.

Identity-platform and supply-chain compromises (Okta 2022/2023, CircleCI 2023, Snowflake-related 2024, MOVEit 2023) continue to produce ecosystem-scale damage that no single benchmark captures cleanly. The 2026 cost picture for these incident types is probably best estimated as 5-15x the directly-reported provider-side cost, given the customer-of-customer cleanup work that ripples through the ecosystem.

How to Use These Benchmarks

Three rules of thumb for using published incident-cost benchmarks responsibly.

  • Anchor to your sector and size, not the global mean. The IBM CODB 2026 headline of $4.99M is an aggregate across an extremely heterogeneous population. For a 1,000-employee mid-market SaaS company, the more relevant anchor is the technology-sector average ($4.79M, IBM CODB 2025 edition) adjusted by size cohort. For a small county government, anchor to the public-sector average ($2.86M, 2025 edition) adjusted by size and known municipal-ransomware comparables.
  • Use multiple sources for the same question. If you are estimating ransomware exposure, look at IBM CODB ransomware-specific data, Sophos ransomware-specific recovery cost, Coveware median ransom, and Mandiant M-Trends dwell-time data. Triangulate; do not pick one number and treat it as truth.
  • Document your assumptions. Loss-given-incident estimates that go into capital-planning, cyber insurance buying, or board-level risk reporting should explicitly cite which benchmarks were used, why they were chosen, and what adjustments were applied. Defensible methodology matters more than precise numbers.

Frequently Asked Questions

Which 2026 incident-cost benchmarks should I use?
Use the source that matches your question. Per-breach average cost across industries: IBM CODB 2026. Ransomware-specific cost: Sophos State of Ransomware 2025 and Coveware quarterly. Breach-cause distribution and dwell time: Verizon DBIR 2026. Underwriter view of cyber claims: Resilience Cyber Risk Report 2025. BEC and wire-fraud loss: FBI IC3 2024. Nation-state activity: Mandiant M-Trends 2026.
What does the IBM CODB 2026 say is the global average?
$4.99M per breach globally, a record high, up 12% from $4.44M the prior year. The rise reverses the prior edition's first-ever decline, and IBM ties it largely to AI-enabled attacks and a longer 247-day detection-and-containment lifecycle. US average was $11.5M, more than double the global figure and the highest of any country. Healthcare remained the costliest sector at $6.64M, down 10.5% YoY.
What does Verizon DBIR 2026 add?
DBIR's value is breach-cause distribution and threat-actor analysis rather than dollar figures. Key 2026 numbers: human element involved in 62% of breaches, ransomware involved in 48% of breaches (up from 44% in the 2025 edition), and vulnerability exploitation overtaking stolen credentials as the leading initial-access vector (31% versus 13%). The DBIR is the preferred source for understanding how breaches happen rather than what they cost.
What is the latest Sophos ransomware data?
Sophos State of Ransomware 2025 reports the mean recovery cost (excluding ransom) at $1.53M cross-industry, down from $2.73M; Sophos State of Ransomware in Healthcare 2025 puts healthcare recovery at $1.02M, down 60% from $2.57M in 2024. Healthcare mean ransom payment fell to $150K (from $1.47M) and the median ransom demand dropped 91% to $343K.
What does Coveware quarterly data tell us?
Coveware data is the closest to ground-truth on actual ransomware behaviour. Recent trends: median ransom payment fluctuating $150K-$400K, median downtime 16-24 days, payment rate continuing to decline (under 30% in recent quarters), and a shift toward exfiltration-only extortion.
What does the FBI IC3 2024 report show?
FBI IC3 Internet Crime Report 2024 documents complaint losses exceeding $16B, with BEC losses exceeding $2.9B and ransomware-reported losses exceeding $59M (a substantial undercount because most ransomware victims do not report to IC3). Average BEC loss per incident was approximately $137,000.
How do these benchmarks reconcile with each other?
They do not all measure the same thing, so apparent contradictions usually reflect different methodologies. IBM CODB measures average cost across all breaches surveyed. Sophos measures recovery cost in ransomware specifically. Coveware measures actual ransom paid. IC3 measures reported loss. Use each for its question and triangulate where possible.
IncidentCost.com is an independent educational resource. All cost figures are drawn from published industry research including IBM's Cost of a Data Breach Report, Ponemon Institute Cost of Insider Risks Report, Verizon Data Breach Investigations Report, Atlassian incident management research, and PagerDuty incident surveys. This site is not affiliated with IBM, Ponemon Institute, Verizon, Atlassian, PagerDuty, or any security vendor. Figures are for educational and planning purposes only.